Self-Hosted • Zero-Knowledge • Open Source

Your master password
never leaves your device.

VaultX is a self-hosted password manager where all encryption happens client-side using Argon2id and XChaCha20-Poly1305. Your server stores only opaque ciphertext. Even if the database is leaked, zero secrets are exposed.

Quick Deploy
$ git clone https://github.com/PiyushY111/VaultX.git && cd VaultX
$ cp .env.example .env
$ docker compose up -d --build
Security Architecture

How It Works

Three mathematical guarantees ensure complete privacy.

01

Local Key Derivation

Your master password is never transmitted. When logging in, your browser stretches it locally using Argon2id (64 MiB RAM, 3 passes), then uses HKDF to split it into two independent keys:

  • Stretched Master Key: Stays strictly in client RAM to decrypt the vault key.
  • Auth Hash: Sent to the server for authentication only. It cannot decrypt your data.
02

Authenticated Encryption

Every credential is encrypted with XChaCha20-Poly1305 under a random 256-bit vault key.

  • Fresh Nonces: A random 24-byte nonce is generated on every single save.
  • Anti-Rollback Ledger: The item ID and monotonic revision counter are bound into the AEAD authenticated data. The server cannot swap or roll back items.
03

Opaque Server Storage

The Fastify + PostgreSQL backend only ever handles opaque ciphertext strings.

  • Zero Plaintext Leaks: Audited by tests that scan raw database tables.
  • RAM Purging: Keys and plaintexts are wiped with sodium.memzero on lock or idle timeout.
User Guide

How to Use VaultX

A streamlined workflow for daily password management.

Step 1

Create an Account

Open the web vault (http://localhost:5173) and set your master password. The built-in entropy meter audits password strength client-side.

Step 2

Add Logins & Secure Notes

Store usernames, passwords, URLs, and notes. Use the cryptographic generator to create random, high-entropy 24+ character passwords.

Step 3

Autofill with Chrome Extension

Load the Manifest V3 extension. When visiting saved websites, 1-click autofill enters your credentials safely without background scraping.

Step 4

Auto-Lock & Manage Sessions

Your vault auto-locks on inactivity. Inspect active browser sessions in the Security panel and revoke remote devices anytime.

Self-Hosting Guide

Setup VaultX

Deploy with Docker Compose or run the local development stack.

1

Clone repository & configure environment

git clone https://github.com/PiyushY111/VaultX.git && cd VaultX cp .env.example .env
2

Set secrets in .env

Generate 32-byte secrets for POSTGRES_PASSWORD and PRELOGIN_SECRET:

openssl rand -base64 32
3

Start API and PostgreSQL

Runs Fastify API and PostgreSQL 17 in background containers:

docker compose up -d --build

The API starts at http://127.0.0.1:3000 and applies database migrations automatically.